Security
Secure by design.
URTM connects to the systems you already run and secures the intelligence layer on top. Your data stays where it lives, access is enforced down to the row, and everything runs encrypted and audited on Microsoft Azure.
Built on Microsoft Azure
What URTM Is
The layer between your systems and better decisions.
We connect your data, apply your business logic, and deliver ready-to-use intelligence for every team.
Your Systems
- ERP
- Accounting
- CRM
- HRIS
- Spreadsheets
Operational Intelligence
Team-Ready Action
- Dashboards
- Reports
- Forecasts
- Alerts
- EagleEye AI
Connect, Don't Copy
Your systems stay your systems.

URTM doesn't ask you to upload your business into another product. It reads from the systems you already run with governed, least-privilege access. The question isn't whether you can trust another platform with everything; it's whether access is governed, scoped, and auditable.
- No migration — your systems stay your systems
- No unnecessary duplication: we connect to governed sources, not become another system of record
- Access governed to your policy, down to the row
- Built on Azure PaaS + Power BI, maintained for you
Configured. Maintained. Audited.
Controls that stay current.
A defense-in-depth set of controls across Microsoft Azure, identity, and operations. Configured to your governance policy and maintained as part of the service, not handed to your team as a checklist.
Access by row
Access is enforced down to the individual row, configured and maintained to your governance policy, with optional object-level security on sensitive tables.
Secure sign-on
OIDC sign-on with PKCE on the Microsoft identity platform. Short-lived tokens are exchanged server-side, with no secrets stored in the browser.
Encrypted everywhere
Traffic uses TLS 1.2+ over HTTPS-only endpoints with HSTS. Data at rest is encrypted with Azure-managed keys across Azure SQL and storage.
Audit-ready
Authentication, access, and configuration changes are logged through Azure Monitor and Application Insights. Customer data is not written to application logs.
Tenant-isolated
Role-based access is enforced at the application layer. Each user is scoped to their tenant, with workspace isolation preventing cross-tenant exposure.
Least-privilege
Production access is scoped to the work required, time-bound where possible, and reviewed regularly. Administrative actions are logged and monitored.
No New Source of Record
Data stays governed.
The biggest reduction in risk surface is simple: URTM operates on your data where it already lives.
Connect
Secure access to your systems
URTM reads from the systems and data platforms you already run through secure, least-privilege connections configured for analytics and reporting.
Minimize
Only what the work requires
The Customer Portal isn't a new source of record. Data stays in your source systems, with only the processing required to deliver analytics, reporting, and visualization.
Read-only
Source systems stay untouched
URTM does not write back to or alter source-system data. Your source systems remain the operational record.
Retain
You control what's kept
Retention and deletion follow your policy. Nothing lingers as an independent copy beyond what a live view needs to render.
Certified Foundation
Built on enterprise infrastructure.
Under a shared-responsibility model, Microsoft secures and audits the infrastructure; URTM implements the application-level controls, access model, and operational safeguards on top.
Compliance-ready
The Customer Portal runs on Microsoft Azure, inheriting applicable certifications from the underlying Microsoft platform.
SOC 1 / SOC 2 / SOC 3
ISO 27001 / ISO 27018
GDPR / CCPA support
Full list available in the Trust Center.
Governed AI
Same controls. Smarter answers.
Eagle Eye and the MCP Server follow the same access, governance, and traceability rules as every other URTM surface. AI is not bolted on outside the security model.

Access-governed
EagleEye and the MCP Server honour the same row-level access controls. They only answer from data the caller is authorized to see.
Grounded
Answers trace back to reconciled source data and expose the figures behind the response. No invented metrics.
Not training data
Customer data is not used to train foundation models. AI sub-processors are assessed for security, privacy, and data protection before use.
Human oversight
AI assists the work; it does not run unsupervised. Outputs remain reviewable, attributable, and governed.
Also Covered
The rest of the diligence package.
The controls your security team asks for next, documented in full in the Trust Center.
- Penetration testing & vulnerability management
- Incident response & breach notification
- Data retention & deletion
- Backups & disaster recovery
- Sub-processor register
- Employee security training
Request the full package in the Trust Center →